Fri, Jun 30 2006 7:12 Don

Apple iTunes AAC File Parsing Integer Overflow Vulnerability


Secunia Advisory:
SA20891
Release Date: 2006-06-30

Description:
A vulnerability has been reported in Apple iTunes, which can be exploited by malicious people to compromise a user's system.

The vulnerability is caused due to an integer overflow error within the parsing of AAC media files (e.g. ".M4A" and ".M4P" file extensions). This can be exploited to cause a memory corruption when a malicious AAC file with a specially crafted "sample_size_table" value is opened.

Successful exploitation allows execution of arbitrary code.

The vulnerability has been reported in versions prior to 6.0.5.

Solution:
Update to version 6.0.5.
http://www.apple.com/itunes/download/
Filed under: